Show filters
140 Total Results
Displaying 41-50 of 140
Sort by:
Attacker Value
Unknown

CVE-2008-2581

Disclosure Date: July 15, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 has unknown impact and remote attack vectors related to UDDI Explorer.
0
Attacker Value
Unknown

CVE-2008-0895

Disclosure Date: February 22, 2008 (last updated October 04, 2023)
BEA WebLogic Server and WebLogic Express 6.1 through 10.0 allows remote attackers to bypass authentication for application servlets via crafted request headers.
0
Attacker Value
Unknown

CVE-2008-0902

Disclosure Date: February 22, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 6.1 through 10.0 MP1 allow remote attackers to inject arbitrary web script or HTML via unspecified samples. NOTE: this might be the same issue as CVE-2007-2694.
0
Attacker Value
Unknown

CVE-2008-0901

Disclosure Date: February 22, 2008 (last updated October 04, 2023)
BEA WebLogic Server and Express 7.0 through 10.0 allows remote attackers to conduct brute force password guessing attacks, even when account lockout has been activated, via crafted URLs that indicate whether a guessed password is successful or not.
0
Attacker Value
Unknown

CVE-2008-0900

Disclosure Date: February 22, 2008 (last updated October 04, 2023)
Session fixation vulnerability in BEA WebLogic Server and Express 8.1 SP4 through SP6, 9.2 through MP1, and 10.0 allows remote authenticated users to hijack web sessions via unknown vectors.
0
Attacker Value
Unknown

CVE-2008-0869

Disclosure Date: February 21, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in BEA WebLogic Workshop 8.1 through SP6 and Workshop for WebLogic 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via a "framework defined request parameter" when using WebLogic Workshop or Apache Beehive NetUI framework with page flows.
0
Attacker Value
Unknown

CVE-2007-5576

Disclosure Date: October 18, 2007 (last updated October 04, 2023)
BEA Tuxedo 8.0 before RP392 and 8.1 before RP293, and WebLogic Enterprise 5.1 before RP174, echo the password in cleartext, which allows physically proximate attackers to obtain sensitive information via the (1) cnsbind, (2) cnsunbind, or (3) cnsls commands.
0
Attacker Value
Unknown

CVE-2007-4613

Disclosure Date: August 31, 2007 (last updated October 04, 2023)
SSL libraries in BEA WebLogic Server 6.1 Gold through SP7, 7.0 Gold through SP7, and 8.1 Gold through SP5 might allow remote attackers to obtain plaintext from an SSL stream via a man-in-the-middle attack that injects crafted data and measures the elapsed time before an error response, a different vulnerability than CVE-2006-2461.
0
Attacker Value
Unknown

CVE-2007-4616

Disclosure Date: August 31, 2007 (last updated October 04, 2023)
The SSL server implementation in BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.0, 9.1, 9.2 Gold through MP1, and 10.0 sometimes selects the null cipher when no other cipher is compatible between the server and client, which might allow remote attackers to intercept communications.
0
Attacker Value
Unknown

CVE-2007-4615

Disclosure Date: August 31, 2007 (last updated October 04, 2023)
The SSL client implementation in BEA WebLogic Server 7.0 SP7, 8.1 SP2 through SP6, 9.0, 9.1, 9.2 Gold through MP2, and 10.0 sometimes selects the null cipher when others are available, which might allow remote attackers to intercept communications.
0